Privacy Policy

Last updated: September 27, 2026

1. Who is responsible (controller)

The controller responsible for processing your personal data under the EU General Data Protection Regulation (GDPR) is Joerg Lange, who operates TreeNotes:

TreeNotes — operated by Joerg Lange
Kirchfeldstr. 39
40882 Ratingen, Germany
Email: contact@treenotes.com — or via the Contact page

2. The short version

  • Your notes, attachments, and their titles are end-to-end encrypted on your device. We store only encrypted data and cannot read it. There is no exception to this.
  • We collect the minimum needed to run the service: your email address, account data, payment status for paid plans, and technical server logs.
  • We use no advertising and no tracking without your consent. Google Analytics on the public website runs only if you actively accept it in the cookie banner. We also derive first-party service statistics from account activity (Section 3.4).
  • You can delete your account and all your data at any time on the Delete Account page.

The rest of this policy explains the details.

3. What data we process

3.1 Account data

When you create an account we process your username, optional email address, optional first and last name, and cryptographic public keys used to verify your login. We never receive or store your password — your device proves your identity with a cryptographic signature, and your password never leaves it.

If you sign up or sign in with Google, we receive your email address and basic profile information (name) from Google. We do not receive your Google password.

If you sign up or sign in with Apple ("Sign in with Apple"), we receive from Apple a user ID for TreeNotes and, if you share it, your email address. If you choose "Hide My Email", this is an Apple relay address that forwards to you. We do not store a name from Apple and do not receive your Apple ID password. We also keep an Apple authorization token, encrypted on our servers, so that deleting your TreeNotes account can revoke TreeNotes' access at Apple.

For both providers we store the provider's user ID and the email address it gives us, linked to your account, so that you can sign in with it again. Your notes stay encrypted either way: after signing in with Google or Apple you unlock them with your own encryption passphrase, which neither the provider nor we receive.

3.2 Content data (end-to-end encrypted)

Your notes, documents, and file attachments are encrypted on your device before they are sent to us. We store and back up only the encrypted data. What our servers can see is structural and technical metadata: the number and size of your notes and attachments, their position in your tree, timestamps, and with whom you have shared a note. What our servers cannot see is any content — including note titles.

An optional profile picture is stored the same way, as an encrypted attachment.

3.3 Payment data

Paid subscriptions are processed by our payment provider Stripe. Stripe collects and processes your payment details (e.g. card number) directly — we never see or store them. We store your subscription plan, its status, and billing period, and we receive confirmation of payments from Stripe.

3.4 Technical data and server logs

When you use TreeNotes, our servers automatically log technical data: a shortened IP address, date and time of the request, the requested endpoint, browser/device information (user agent), and the response status. We use these logs to operate the service securely, detect abuse, and diagnose errors. Log entries are deleted after 30 days.

We shorten the IP address before writing it to the log — we keep only the network portion (the first three blocks of an IPv4 address, the first three groups of an IPv6 address) and discard the rest. That is enough to recognise abuse patterns, and it means the log does not contain an address that identifies your individual connection.

We also retain account-linked sign-in activity, device/session labels, preferences, consent choices, favorites and recently opened item identifiers. These support authentication, security, settings and navigation. We derive aggregate service statistics, including account counts, active-account counts and storage/sharing totals, from these records. This first-party processing is separate from optional website Google Analytics.

3.5 Communication

If you contact us (contact form, issue report, or email), we process your message and contact details in order to respond. The contact form is protected by hCaptcha to prevent automated abuse (see Section 7).

We send transactional emails (e.g. email verification, important service or billing notices). We do not send marketing emails without your consent.

4. Purposes and legal bases

Processing Purpose Legal basis (GDPR)
Account, content storage, sync, sharing Providing the service Art. 6(1)(b) — contract
Payment processing, billing records Paid subscriptions Art. 6(1)(b); Art. 6(1)(c) — statutory retention duties
Server logs, abuse prevention, CAPTCHA Security and stability Art. 6(1)(f) — legitimate interest in a secure service
Transactional emails Service operation Art. 6(1)(b)
Sign in with Google or Apple Signing in with an existing provider account, at your choice Art. 6(1)(b)
Push notifications about share invitations (only if you allow them) Telling you about new invitations Art. 6(1)(b)
Analytics (only if you accept) Understanding aggregate usage Art. 6(1)(a) — consent

5. Cookies and local storage

TreeNotes uses only what is technically necessary by default:

  • a session cookie (HttpOnly) that keeps you signed in;
  • local storage in your browser for settings such as language, theme, and your cookie choice.

These are required for the service to function (§ 25(2) TDDDG) and set no tracking.

Optional analytics (Section 6) is loaded only after you consent via the cookie banner. You can decline it with one click, and the service works exactly the same.

5.1 Native mobile apps

The iOS and Android apps keep an encrypted local database for offline notes and pending changes, plus encrypted caches for viewed files and gallery previews. These caches are excluded from normal device backups. Locking closes the vault; it does not delete pending changes. Device storage controls let you clear cached content. Signing out or deleting the account clears the app's local vault and capture keys; cleanup failures are reported so you can retry.

Quick unlock uses the operating system's device authentication and protected key storage (Keychain on iOS, Keystore on Android). TreeNotes does not receive biometric templates, fingerprints or face scans.

When you share text, links, photos, videos or files into TreeNotes, an encrypted capture is saved on the device and imported after you unlock the app. It then syncs using the same end-to-end encryption as other content. Exporting or sharing a file out of TreeNotes temporarily provides a decrypted file to the destination you choose. The app attempts to remove its temporary export file afterwards; copies saved by you or another app remain under that destination's control.

External images in notes and external link previews can contact the destination host, which can receive your IP address and the requested URL. The bundled mobile app does not load the public website's Google Analytics scripts. The account activity and service statistics described in Section 3.4 still apply.

5.2 Push notifications (mobile apps)

The mobile apps can notify you when another TreeNotes user shares a note or folder with you. This happens only if you allow notifications for TreeNotes on your device; you can turn it off at any time in the app's settings or in your device settings.

For this we store, per installation: the platform (iOS or Android), the push token your device's notification service assigns to the app, the language of the device, the sign-in session it belongs to, and when it was registered. On Android, the Firebase Cloud Messaging component also generates a Firebase installation ID that is shared with Google.

Notifications are delivered through Apple Push Notification service (APNs) on iOS and Google Firebase Cloud Messaging (FCM) on Android. Apple or Google therefore receive the push token, the notification text — "sharer's name shared something with you" — and the time. A notification never contains the title or content of a shared item; that is end-to-end encrypted and cannot be read by us either.

We delete the token when you sign out on that device, when you delete your account, or when Apple or Google report that it is no longer valid.

Due-task reminders are different: they are scheduled by the app on your device from your decrypted task lists and never pass through our servers or a push service.

6. Analytics (only with consent)

If — and only if — you accept analytics in the cookie banner, we use Google Analytics 4 (Google Ireland Ltd.) to understand aggregate usage of the public website. Google may transfer data to the United States; Google LLC is certified under the EU–U.S. Data Privacy Framework. You can withdraw your consent at any time in Settings or by clearing your choice in the cookie banner; withdrawal stops analytics from that point on.

If you decline, no analytics scripts are loaded at all.

7. Who receives data (processors and recipients)

We share personal data only with service providers we need to run TreeNotes, under data processing agreements where required:

Recipient Purpose Location / transfer safeguard
Our hosting provider — servers located in the EU Running the servers and database EU
Strato AG (HiDrive) Off-site backup storage. Backups are encrypted before upload; the storage provider cannot read them. Germany
Stripe Payments Europe, Ltd. (and Stripe, Inc.) Payment processing Ireland / USA — EU–U.S. Data Privacy Framework and EU standard contractual clauses
Google Ireland Ltd. / Google LLC Optional "Sign in with Google"; delivery of transactional email; push notifications on Android (Firebase Cloud Messaging); optional analytics (consent only) Ireland / USA — EU–U.S. Data Privacy Framework
Apple Distribution International Ltd. / Apple Inc. Optional "Sign in with Apple"; push notifications on iOS (APNs) Ireland / USA — EU–U.S. Data Privacy Framework
Intuition Machines, Inc. (hCaptcha) Protecting the contact form against bots USA — EU standard contractual clauses / Data Privacy Framework

We do not sell personal data and do not share it with anyone for advertising.

We disclose data to authorities only where we are legally obliged to. Note that even then, we can only hand over what we have: encrypted content we cannot decrypt, plus the metadata described in Section 3.

8. How long we keep data

  • Account and content data: until you delete your account. Deletion removes your account, notes, attachments, shares, and keys from our live systems immediately.
  • Backups: encrypted backups are rotated automatically and expire after at most 12 months; deleted data disappears from backups on that schedule. Backups are used only for disaster recovery, never to restore individual deleted accounts.
  • Push tokens: until you sign out on that device, delete your account, or Apple/Google report the token invalid (Section 5.2).
  • Sign in with Google or Apple: the linked provider ID and email are kept while they are linked to your account; account deletion removes them and revokes TreeNotes' access at Apple.
  • Server logs: 30 days.
  • Billing records: retained as long as tax and commercial law require (in Germany currently up to 10 years); this applies to invoices, not to your content.
  • Support communication: as long as needed to handle your request, then deleted within a reasonable period.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17) — most easily via Delete Account,
  • restriction of processing (Art. 18),
  • data portability (Art. 20) — you can export your notes yourself at any time from within the app,
  • object to processing based on legitimate interests (Art. 21), and
  • withdraw consent at any time with effect for the future (Art. 7(3)), e.g. for analytics.

To exercise these rights, contact us via the Contact page. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77), for example the authority of the German federal state where you live.

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

10. Security

All connections are TLS-encrypted. Content is end-to-end encrypted on your device using established, published cryptography (Argon2, AES-GCM, X25519, Ed25519). Passwords are never transmitted or stored; authentication uses digital signatures. Backups are encrypted before leaving our infrastructure. A detailed technical description is on our Security page.

One important consequence of this design: because we never have your password or your keys, we cannot reset your password or recover your content if you lose your credentials. Please keep them safe.

11. Children

TreeNotes is not directed at children. You must be at least 16 years old to use the service.

12. Changes to this policy

We will update this policy when the service or the law changes. The current version is always available at this address; the date above shows when it was last revised. If a change materially affects your rights, we will inform you in the app or by email.